HGiga MailSherlock mail query function has vulnerability of insufficient validation for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inject SQL commands to read, modify, and delete the database.
References
Link | Resource |
---|---|
https://www.twcert.org.tw/tw/cp-132-6959-cdecb-1.html | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: twcert
Published: 2023-03-27T00:00:00
Updated: 2023-03-27T00:00:00
Reserved: 2023-01-31T00:00:00
Link: CVE-2023-24840
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-03-27T04:15:10.087
Modified: 2023-03-30T17:56:58.790
Link: CVE-2023-24840
JSON object: View
Redhat Information
No data.
CWE